Executive Summary
Security researchers have identified an active, accelerating campaign attributed to the EvilTokens Phishing-as-a-Service (PhaaS) platform, operated by the NOIRLEGACY GROUP. The campaign targets Microsoft 365 identities across over 340 organizations globally, including those in the US, Canada, and Germany. The primary methodology involves weaponizing Railway.com, a Platform-as-a-Service (PaaS) provider, to host token-replay engines and credential-harvesting infrastructure. This approach leverages Railway's legitimate IP reputation to bypass risk-based scoring and automated email filters.
The attack is technically mature, utilizing AI-driven lures and sophisticated delivery chains that include multi-hop redirects and the abuse of email security vendor URL rewriters (e.g., Cisco, Trend Micro, Mimecast). By exploiting the OAuth device authorization flow, attackers obtain persistent tokens that remain valid even after password resets and effectively bypass Multi-Factor Authentication (MFA). Immediate defensive actions include blocking Railway CIDR blocks and hunting for specific behavioral Indicators of Compromise (IoCs) within identity logs.
